Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute arbitrary JavaScript via the file preview function. Users can upload HTML/CSS/JS files into the Xibo Library via the Generic File module to be referenced on Displays and in Layouts. This is intended functionality. When previewing these resources from the Library and Layout editor they are executed in the users browser. This will be disabled in future releases, and users are encouraged to use the new developer tools in 4.1 to design their widgets which require this type of functionality. This behavior has been changed in 4.1.0 to preview previewing of generic files. There are no workarounds for this issue.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Sep 2024 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xibosignage
Xibosignage xibo |
|
CPEs | cpe:2.3:a:xibosignage:xibo:*:*:*:*:*:*:*:* | |
Vendors & Products |
Xibosignage
Xibosignage xibo |
Tue, 03 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 03 Sep 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute arbitrary JavaScript via the file preview function. Users can upload HTML/CSS/JS files into the Xibo Library via the Generic File module to be referenced on Displays and in Layouts. This is intended functionality. When previewing these resources from the Library and Layout editor they are executed in the users browser. This will be disabled in future releases, and users are encouraged to use the new developer tools in 4.1 to design their widgets which require this type of functionality. This behavior has been changed in 4.1.0 to preview previewing of generic files. There are no workarounds for this issue. | |
Title | Xibo CMS XSS vulnerability when previewing files uploaded to the library containing HTML/JS | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-03T16:52:23.643Z
Updated: 2024-09-03T17:43:03.820Z
Reserved: 2024-08-12T18:02:04.967Z
Link: CVE-2024-43412
Vulnrichment
Updated: 2024-09-03T17:42:58.691Z
NVD
Status : Analyzed
Published: 2024-09-03T17:15:14.680
Modified: 2024-09-12T20:20:56.763
Link: CVE-2024-43412
Redhat
No data.